Category: Cyber Threat

AWS KMS Ransomware Hunt — when encryption keys become the attacker's weapon · HackForLab AWS Threat Hunting series Part 2
0 63
Posted in Cyber Threat

AWS KMS Ransomware Hunt: When Your Encryption Keys Become the Attacker’s Weapon

Adversaries are increasingly weaponising AWS KMS for ransomware — encrypting victim data with attacker-controlled keys, modifying key policies to lock out the legitimate owner, and using grant tokens for stealth access. This hunt playbook covers the techniques, the detection logic, and the response actions for KMS-mediated ransomware.

CloudTrail Blind Spots — 12 places AWS doesn't log and how to hunt there anyway · HackForLab AWS Threat Hunting series Part 1
0 65
Posted in Cyber Threat

CloudTrail Blind Spots: 12 Places AWS Doesn’t Log (And How to Hunt There Anyway)

CloudTrail is the cornerstone of AWS threat detection — but it has structural blind spots adversaries deliberately exploit. This guide maps 12 places CloudTrail does not log by default, the techniques that abuse each gap, and the compensating hunt patterns that fill the visibility hole.

HACKFORLAB Threat Hunting Playbook · June 1-7, 2026 · Hunt hypotheses, query patterns, detection engineering recipes · open-source C2 frameworks, Linux backdoors, helpdesk impersonation extortion, APT campaigns, supply chain worms, commodity RATs, IoT botnets
0 86
Posted in Cyber Threat

The Threat Hunter’s Sigma Playbook: 7 Hunts Every Modern SOC Must Run

A 2026 threat hunting playbook with seven battle-tested Sigma rules, a MITRE ATT&CK coverage matrix, and success metrics for SOC analysts, threat hunters, and detection engineers. Hunt the techniques, not the indicators.

What Cloud Logs You Actually Need to Hunt — log dependency map across AWS, Azure, and GCP for threat hunting · VPC Flow · CloudTrail · K8s Audit · coverage · blind spots
0 77
Posted in Cyber Threat

What Cloud Logs You Actually Need for Threat Hunting (And Why Most Teams Fail)

A practitioner’s guide to the minimum viable cloud log set: CloudTrail, identity, DNS at tier one. Coverage matrix across AWS, Azure, GCP plus cost trade-offs.

A Practical Detection Engineering Framework — 5-stage lifecycle from hypothesis to shipped rule used by modern SOCs · Hypothesis · Data · Logic · Validation · Metrics
0 80
Posted in Cyber Threat

A Practical Detection Engineering Framework Used by Modern SOCs

A five-stage detection engineering framework — hypothesis, data inventory, logic, validation, metrics — with an AWS GuardDuty worked example, YAML rule template, and a failure-analysis playbook for noisy or silent detections.